CVE-2026-25897: ImageMagick has heap overflow in sun decoder on 32-bit systems that can result in out of bounds write

Published Feb 24, 2026
·
Updated

An Integer Overflow vulnerability exists in the sun decoder. On 32-bit systems/builds, a carefully crafted image can lead to an out of bounds heap write.

================================================================= ==1967675==ERROR: AddressSanitizer: heap-buffer-overflow on address 0xf190b50e at pc 0x5eae8777 bp 0xffb0fdd8 sp 0xffb0fdd0 WRITE of size 1 at 0xf190b50e thread T0

Other sources

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, an Integer Overflow vulnerability exists in the sun decoder. On 32-bit systems/builds, a carefully crafted image can lead to an out of bounds heap write. Versions 7.1.2-15 and 6.9.13-40 contain a patch.

NVD

Affected Software

21 affected componentsFixes available
ImageMagick ImageMagick<7.1.2-15, <6.9.13-40
nuget/Magick.NET-Q8-x86<14.10.3
14.10.3
nuget/Magick.NET-Q8-arm64<14.10.3
14.10.3
nuget/Magick.NET-Q8-OpenMP-x64<14.10.3
14.10.3
nuget/Magick.NET-Q8-OpenMP-arm64<14.10.3
14.10.3
nuget/Magick.NET-Q8-AnyCPU<14.10.3
14.10.3
nuget/Magick.NET-Q16-x86<14.10.3
14.10.3
nuget/Magick.NET-Q16-arm64<14.10.3
14.10.3
nuget/Magick.NET-Q16-OpenMP-x86<14.10.3
14.10.3
nuget/Magick.NET-Q16-OpenMP-x64<14.10.3
14.10.3
nuget/Magick.NET-Q16-OpenMP-arm64<14.10.3
14.10.3
nuget/Magick.NET-Q16-HDRI-x86<14.10.3
14.10.3
nuget/Magick.NET-Q16-HDRI-x64<14.10.3
14.10.3
nuget/Magick.NET-Q16-HDRI-arm64<14.10.3
14.10.3
nuget/Magick.NET-Q16-HDRI-OpenMP-x64<14.10.3
14.10.3
nuget/Magick.NET-Q16-HDRI-OpenMP-arm64<14.10.3
14.10.3
nuget/Magick.NET-Q16-HDRI-AnyCPU<14.10.3
14.10.3
nuget/Magick.NET-Q16-AnyCPU<14.10.3
14.10.3
ImageMagick ImageMagick<6.9.13-40
ImageMagick ImageMagick>=7.0.0-0<7.1.2-15
debian/imagemagick<=8:6.9.11.60+dfsg-1.3+deb11u4, <=8:6.9.11.60+dfsg-1.6+deb12u5, <=8:7.1.1.43+dfsg1-1+deb13u5
8:6.9.11.60+dfsg-1.3+deb11u128:6.9.11.60+dfsg-1.6+deb12u98:7.1.1.43+dfsg1-1+deb13u88:7.1.2.18+dfsg1-18:7.1.2.21+dfsg1-1

Event History

Feb 24, 2026
CVE Published
via MITRE·01:16 AM
Data Sourced
via MITRE·01:16 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:16 AM
DescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·03:38 PM
Data Sourced
via GitHub·03:38 PM
DescriptionSeverityWeaknessAffected Software
May 13, 2026
Data Sourced
via Debian·04:06 AM
DescriptionAffected Software
Data Sourced
via Launchpad·04:06 AM
Description
May 14, 2026
Data Sourced
via Ubuntu·04:06 AM
RemedyDescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-25897?

CVE-2026-25897 is classified as a critical vulnerability due to its potential for heap overflow and out-of-bounds writes on 32-bit systems.

2

How do I fix CVE-2026-25897?

To fix CVE-2026-25897, upgrade ImageMagick to version 7.1.2-15 or 6.9.13-40 or later.

3

Which versions of ImageMagick are affected by CVE-2026-25897?

CVE-2026-25897 affects versions of ImageMagick prior to 7.1.2-15 and 6.9.13-40.

4

What systems are primarily impacted by CVE-2026-25897?

CVE-2026-25897 primarily impacts 32-bit systems when processing specially crafted images.

5

Is there a workaround for CVE-2026-25897?

Currently, the recommended workaround for CVE-2026-25897 is to upgrade to a non-vulnerable version of ImageMagick.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203